2026 CVE Vulnerabilities
64,705 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19599 | CRITICAL | 9.9 | — | Sep 23, 2026 | ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability... |
| CVE-2026-86350 | CRITICAL | 9.1 | — | Sep 23, 2026 | Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused... |
| CVE-2026-86248 | CRITICAL | 9.8 | — | Sep 23, 2026 | CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apac... |
| CVE-2026-76183 | CRITICAL | 9.8 | — | Sep 23, 2026 | Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocke... |
| CVE-2026-82331 | CRITICAL | 9.8 | 0.2% | Sep 23, 2026 | Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildS... |
| CVE-2026-82843 | CRITICAL | 9 | 0.2% | Sep 23, 2026 | The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity ass... |
| CVE-2026-75799 | CRITICAL | 9 | 0.2% | Sep 23, 2026 | The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly... |
| CVE-2026-96257 | CRITICAL | 10 | 1.0% | Sep 23, 2026 | A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of... |
| CVE-2026-18169 | CRITICAL | 9.9 | 0.8% | Sep 22, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensi... |
| CVE-2026-18163 | CRITICAL | 9.8 | 0.8% | Sep 22, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due... |
| CVE-2026-18162 | CRITICAL | 9.8 | 0.9% | Sep 22, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due... |
| CVE-2026-19202 | CRITICAL | 9.1 | 0.2% | Sep 22, 2026 | A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cache... |
| CVE-2026-17645 | CRITICAL | 9.1 | 0.6% | Sep 22, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to gain elevate... |
| CVE-2026-17635 | CRITICAL | 9.1 | 0.5% | Sep 22, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actio... |
| CVE-2026-17472 | CRITICAL | 9.6 | 0.4% | Sep 22, 2026 | IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources d... |
| CVE-2026-16346 | CRITICAL | 9.9 | 0.6% | Sep 22, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du... |
| CVE-2026-77987 | CRITICAL | 9.3 | 0.9% | Sep 22, 2026 | A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. Th... |
| CVE-2026-89282 | CRITICAL | 9.1 | 0.2% | Sep 22, 2026 | The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissio... |
| CVE-2026-88624 | CRITICAL | 9.1 | 0.3% | Sep 22, 2026 | Missing path validation in the Worktree.remove component of openCode v1.18.26 allows attackers to execute arbitrary recu... |
| CVE-2026-87121 | CRITICAL | 9.8 | 0.8% | Sep 22, 2026 | lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution ... |
| CVE-2026-76709 | CRITICAL | 9.8 | 0.7% | Sep 22, 2026 | A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Successful explo... |
| CVE-2026-76708 | CRITICAL | 9.8 | 0.6% | Sep 22, 2026 | A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system ... |
| CVE-2026-47116 | CRITICAL | 9.8 | 0.5% | Sep 22, 2026 | LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where the root and guest account passwords are stor... |
| CVE-2026-28324 | CRITICAL | 9.8 | 0.7% | Sep 22, 2026 | SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability ... |
| CVE-2026-91130 | CRITICAL | 9.3 | 0.5% | Sep 22, 2026 | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Stat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now